TROJ_DLOADER.CHN
Windows 2000, XP, Server 2003

Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
However, as of this writing, the said sites are inaccessible.
It is a component of other malware.
It connects to certain URLs. It may do this to remotely inform a malicious user of its installation. It may also do this to download possibly malicious files onto the computer, which puts the computer at a greater risk of infection by other threats.
TECHNICAL DETAILS
Arrival Details
However, as of this writing, the said sites are inaccessible.
Installation
This Trojan is a component of other malware.
Download Routine
This Trojan connects to the following malicious URLs:
- http://{BLOCKED}.{BLOCKED}5.233.32/e525.gif
- http://{BLOCKED}.{BLOCKED}5.233.32/e514.gif
- http://{BLOCKED}.{BLOCKED}5.233.32/e511.gif
- http://{BLOCKED}.{BLOCKED}5.233.32/count.php?{random}
SOLUTION
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Step 2
Scan your computer with your Trend Micro product and note files detected as TROJ_DLOADER.CHN
Step 3
Restart in Safe Mode
Step 4
Search and delete the file detected as TROJ_DLOADER.CHN
Did this description help? Tell us how we did.